Latest News

Coldcard Theft Case Update: FBI May Have Identified…

Investigators probing the large-scale theft of Bitcoin from vulnerable Coldcard wallets may have uncovered information capable of identifying the attacker behind the first and largest wave, although the FBI has not publicly confirmed a suspect, arrest or recovery of funds.

The development follows an investigation led by Clay Garrett, engineering lead at Block working on its Bitkey Bitcoin wallet. According to an August 18 report from Bitcoin Magazine, Garrett’s team discovered an unusual pattern while examining the transactions that drained 1,082.65 BTC from 1,196 addresses during a roughly 41-minute period on July 30.

The researchers concluded that the attacker had used a paid account at a major blockchain data provider to query source addresses and perform other activity connected to the theft. Block subsequently contacted the provider, whose internal records reportedly matched the timing, number and sequence of requests associated with the attack with unusually high specificity.

That creates an important investigative trail outside Bitcoin’s blockchain. A paid service account can potentially contain subscriber, payment, access or network information that law enforcement could use alongside on-chain evidence to identify its operator.

First-Wave Bitcoin Remains Unmoved

Galaxy Research head Alex Thorn said during a Bitcoin Magazine discussion that the identity of the first-wave attacker “may be known to law enforcement.” Block has said relevant information was passed to appropriate authorities.

The claim remains unconfirmed by the FBI. As of August 19, there has been no publicly announced arrest, indictment, seizure or recovery connected to the first-wave attacker, making a distinction between investigators possessing an identifying lead and authorities formally establishing a suspect important.

The 1,082.65 BTC taken during the first wave also remains unmoved, according to the latest reporting. At Bitcoin prices around $64,000, that position is currently worth roughly $69 million.

Researchers have identified additional waves beyond the initial July 30 sweep. Galaxy has estimated that at least 1,700 BTC was stolen across the incident, while other researchers have published higher figures depending on which address clusters and suspected transactions are included.

A second wave involving roughly 76 BTC displayed characteristics sufficiently similar to the first that researchers have considered the possibility of the same attacker, though that connection has not been established.

Coldcard Flaw Leaves Existing Seeds Exposed

The theft originated from a flaw affecting seed generation in versions of Coldcard firmware. Researchers found that defective random-number-generation checks could result in insufficient entropy when creating wallet seeds, reducing the search space enough for a sophisticated attacker to reconstruct private keys under certain conditions.

That distinction is significant because the Bitcoin network itself was not compromised, nor did attackers necessarily need physical access to the affected hardware wallets. Instead, the weakness existed in how some Coldcard devices generated the secret information ultimately controlling users’ Bitcoin.

Coinkite has released firmware addressing the flaw, but installing patched firmware does not repair recovery phrases that were generated using vulnerable software. Owners of potentially affected wallets must generate a new seed using corrected firmware and migrate their Bitcoin to addresses controlled by the new keys.

The investigative breakthrough also illustrates the limits of relying solely on blockchain pseudonymity. Bitcoin transactions can be followed indefinitely on-chain, but attribution often depends on connecting those transactions with off-chain infrastructure.

If the paid blockchain-data account can ultimately be tied to the person controlling the first-wave addresses, investigators could gain their strongest attribution evidence yet. Recovering the Bitcoin would remain a separate challenge, however, particularly while the 1,082.65 BTC remains under the attacker’s control and has not moved through a regulated intermediary capable of responding to a seizure order.

You may also like